CVE Database /
CVE-2022-0450
CVE · Medium
CVE-2022-0450 — Menu Image, Icons made easy [menu-image] < 3.0.8 (closed)
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-0450
|
Menu Image, Icons made easy [menu-image] < 3.0.8 (closed) |
Improper Encoding or Escaping of Output |
Medium
5.4
|
< 3.0.8
|
3.0.8 |
2022-03-07 |
—
|
CVE-2022-0450
The Menu Image, Icons made easy plugin prior to version 3.0.6 failed to implement authorization checks and cross-site request forgery protections on menu settings operations, while also lacking proper input validation and output escaping. This allowed any logged-in user, including those with subscriber-level permissions, to modify menu settings for arbitrary menus and inject malicious scripts that would execute when the affected menus displayed on the website frontend.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings